Utilizamos cookies para ayudarnos a mejorar nuestra página web. Lea nuestra Política de cookies .
2023-06-21
Severity
Status
Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access to sensitive files or directories without appropriate permission restrictions.
Product | Severity | Fixed Release Availability |
---|---|---|
Download Center on ADM 4.2 and 4.1 | Important | Upgrade Download Center to 1.1.5.r1298 or above. |
Download Center on ADM 4.0 | Important | Upgrade Download Center to 1.1.5.r1301 or above. |
Zhiyong Xing, Inner Mongolia Xinyuan Network Security Technology Co., Ltd., China
Revision | Date | Description |
---|---|---|
1 | 2023-05-31 | Initial public release. |
2 | 2023-05-31 | CVE ID (CVE-2023-2749) is assigned for the issue. |
3 | 2023-06-01 | Release Download Center 1.1.5.r1298 for ADM 4.2 to fix the issue. |
4 | 2023-06-21 | Release Download Center 1.1.5.r1301 for ADM 4.0 to fix the issue. |
Copyright © 2025 ASUSTOR Inc.